Splunk Search

Splunk Search
Community Activity
teewenjie22
How to Convert _time             ColumnA                  ColumnB timeA             10                               ...
by teewenjie22 Engager in Splunk Search 01-31-2021
0 3
0
3
landen99
Enable alerts and reports on real-time searches seen in the internal audit index.
by landen99 Motivator in Splunk Search 01-30-2021
0 2
0
2
redfan9
I am a newbie to Splunk and am trying to find out what query I can use to find a specific users browsing history for ...
by redfan9 New Member in Splunk Search 01-30-2021
0 1
0
1
AzmathShaik
Hello All,i have a default app which gets installed on the UF during the installation (part of our install script). t...
by AzmathShaik Path Finder in Splunk Search 01-29-2021
0 4
0
4
shazbot79
Hi, can anyone make any suggestions as to how I can make this search more efficient?  index=prod_service_now sourcety...
by shazbot79 Path Finder in Splunk Search 01-29-2021
0 4
0
4
gn694
I have a search created, and want to get a count of the events returned by date. I know the date and time is stored ...
by gn694 Communicator in Splunk Search 01-29-2021
3 5
3
5
AshChakor
I want to display counts latest two weeks (last two weeks), two weeks before and everything else before 4 weeks start...
by AshChakor Path Finder in Splunk Search 01-29-2021
0 1
0
1
viswatejabolla
Hi All,I have field called stepName which will have below three values.TextResource.getFirstLineTextResource.getSecon...
by viswatejabolla New Member in Splunk Search 01-29-2021
0 3
0
3
marceloalejandr
Greetings,I've 2 Lookup (csv) files, one generated from index _internal (approx 15k events) and another generated fro...
by marceloalejandr Path Finder in Splunk Search 01-29-2021
0 6
0
6
dnsGuy314
I have a current alert that is working as expected to capture a log event that states a service is down. We have sta...
by dnsGuy314 New Member in Splunk Search 01-29-2021
0 10
0
10
dpwtheitguy
All, I have this search here and it's pretty slow. Any recommendations to speed it up? Currently 250.249 seconds and ...
by dpwtheitguy Loves-to-Learn Lots in Splunk Search 01-28-2021
0 2
0
2
deepuhassan
Hi,I have the below query which does the search on two different sources in the same index and join the results based...
by deepuhassan Explorer in Splunk Search 01-28-2021
0 6
0
6
EStallcup
I'm having a bit of trouble trying to backfill a couple days in my summary index from a query using the collect comma...
by EStallcup Path Finder in Splunk Search 01-28-2021
2 14
2
14
fdevera
How would I take the results from this search:| rex field=initiatedBy.user.userPrincipalName "ex(?<GUID>\d+)z\@"And p...
by fdevera Path Finder in Splunk Search 01-28-2021
0 3
0
3
TheBravoSierra
I'm trying to look for senders where they don't contain values from the lookup mimics.csv. Examples of values in the ...
by TheBravoSierra Path Finder in Splunk Search 01-28-2021
0 3
0
3
redrobish1
Been testing to get a ISE-Splunk successful authentication report and trying this but the "Calling-Station-ID" is not...
by redrobish1 Engager in Splunk Search 01-28-2021
0 2
0
2
youngsuh
Here is what I've done.  How to break out the results into individual software correctly in Splunk.  Any tips could b...
by youngsuh Contributor in Splunk Search 01-28-2021
0 3
0
3
alexspunkshell
Hi All,Please help me with splunk query to find removed (Off-boarded) hosts & index in splunk
by alexspunkshell Contributor in Splunk Search 01-28-2021
0 3
0
3
shazbot79
Hi,I have used the Service Now add on to pull in the incident table. We have a custom SNow field called "dv_u_configu...
by shazbot79 Path Finder in Splunk Search 01-28-2021
0 2
0
2
gcue
i am trying to figure out what the output values are not showing up in my pie chart.  i would eventually like to grap...
by gcue Loves-to-Learn in Splunk Search 01-28-2021
0 2
0
2
prettysunshinez
I have a search query that outputs the count of the event for all the host (i.e., | stats count by host)Now if the co...
by prettysunshinez Explorer in Splunk Search 01-28-2021
0 4
0
4
Abha11
I am having an issue with one of my monitor stanza in inputs.conf. The stanza is as below:  [monitor://E:Speech\Tomca...
by Abha11 Explorer in Splunk Search 01-28-2021
0 3
0
3
sweiland
Hello Everyone, We are currently working on exchange logs (IIS), and trying to detect abnormal traffic from different...
by sweiland Path Finder in Splunk Search 01-28-2021
0 10
0
10
DanielAmlung
Hi,iam stuck with a problem where i need help from you guys. I have a search that runs IDs against a lookup to determ...
by DanielAmlung Path Finder in Splunk Search 01-28-2021
0 3
0
3
renSplunk
Hi,I have a query that gives a table of records satisfying certain condition. Have another query that gives the same ...
by renSplunk New Member in Splunk Search 01-28-2021
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...
Top Solution Authors